CVE-2023-7320
BaseFortify
Publication date: 2025-10-29
Last updated on: 2025-10-30
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| woocommerce | woocommerce | 7.8.2 |
| woocommerce | woocommerce | 7.9 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in the WooCommerce plugin for WordPress (up to version 7.8.2) is due to improper handling of Cross-Origin Resource Sharing (CORS) on the Store API's REST endpoints. This flaw allows any external origin to access these endpoints directly without authentication, enabling attackers to extract sensitive user information, including personally identifiable information (PII).
How can this vulnerability impact me? :
An unauthenticated attacker can exploit this vulnerability to access sensitive user data, including personal identifiable information, which could lead to privacy breaches, identity theft, or other malicious activities targeting affected users.